CVE-2026-63235

LOW

Three Learning Koollab Lms < 5.3.2 - Denial of Service

Title source: rule
STIX 2.1

Description

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via the login kickout endpoint, resulting in a denial of service.

Scores

CVSS v3 3.7
EPSS 0.0020
EPSS Percentile 9.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
Three Learning/Koollab LMS 5.3.2
Published Jul 29, 2026
Tracked Since Jul 29, 2026